Latest stories — Page 89

Cloud Security

The Data You Don't Know You Have Is the Data That Will Burn You

DSPM tools are selling fast and consolidating faster — here's why security teams are scrambling to find the data they forgot existed.

3 min read
AI Security

Cisco Uncovers Major Weaknesses in Leading AI Models

Relying solely on single-turn benchmarks could mislead your AI security assessments.

2 min read
AI Security

AI's Role in the Battle of Stolen Credentials

Security teams grapple with AI-driven credential abuse, leaving many playing catch-up.

2 min read
AI Security

SymJack: How a Rogue Symlink Turns Your AI Coding Agent Into a Supply Chain Weapon

A newly documented attack technique exploits AI coding agents through malicious repositories and disguised symlinks, silently planting attacker-controlled MCP servers deep inside developer environments.

3 min read
AI Security

AI Risk Summit Returns August 11–12 at Half Moon Bay for Its Third Year

CISOs, policymakers, and AI researchers converge on the Ritz-Carlton for two days of hard conversation about what enterprise AI risk actually looks like in practice.

2 min read
Vulnerabilities

Account Takeover Flaw in Pretalx CFP Tool Let Attackers Accept Any Conference Talk

An account takeover vulnerability in the open-source call-for-papers platform Pretalx could allow an unauthenticated attacker to manipulate submission outcomes, researchers at Novee have found.

3 min read
AI Security

Microsoft Catches Chatbots Pointing Users at Cryptojacking Sites

A campaign tracked by Microsoft Defender Experts is poisoning AI assistant answers so that download recommendations lead to miner-laden installers.

2 min read
Threat Intelligence

Britain's Cyber Spymaster Calls AI an Unstoppable Force and Points the Finger at Moscow

The head of GCHQ's signals intelligence arm delivered a rare public speech warning that Russia is waging sustained gray-zone aggression — and that artificial intelligence will define who wins the next phase of that conflict.

3 min read
Opinion

The SOC's Real Job Isn't Triage. It's Killing Incidents Before They Get Named.

Three workflow shifts that compress detection-to-containment from hours into the window before an alert becomes a ticket.

2 min read
Vulnerabilities

Gitea Patches Unauthenticated Container Image Disclosure Flaw in 1.26.2

CVE-2026-27771 allowed anonymous pulls of private container images from all Gitea deployments prior to version 1.26.2, according to maintainers.

2 min read
Policy & Regulation

Shadow AI Is Now a Compliance Problem, Not Just an IT One

Employees are running unsanctioned AI assistants by the handful. Regulators are starting to ask who approved them, and under which control framework.

3 min read
Threat Intelligence

CrowdStrike, Google and Shadowserver Pull the Plug on GlassWorm's C2

A coordinated takedown severed every known command channel of the developer-targeting worm — for now.

2 min read
Threat Intelligence

Grandoreiro Hits Spain Again, BTMOB Spreads on Android in Brazil

Two parallel banking trojan campaigns are pulling in victims across Iberia, Mexico, and Brazilian Android users. The lures are mundane. The payloads are not.

3 min read
AI Security

The npm Package That Reached Into Claude's Sandbox

A bait package called mouse5212-super-formatter quietly siphoned files from the directory Anthropic's Claude uses to handle user uploads, exfiltrating them to a GitHub repo controlled by the author.

2 min read
Threat Intelligence

Glassworm's blockchain command channel went down. Nobody will say who pulled the plug.

Researchers say the developer-targeting botnet is offline after its Solana and BitTorrent DHT C2 was disrupted. The mechanics of the takedown, and who authorised it, remain unexplained.

3 min read
Vulnerabilities

CISA Gives Federal Agencies Four Days to Kill a cPanel Plugin Bug Already Being Exploited

The LiteSpeed plugin sits on millions of shared hosting accounts. CISA's compressed timeline says the quiet part loud: someone's already inside.

2 min read
Threat Intelligence

MuddyWater Targets Global Organizations with DLL Side-Loading

Iranian group MuddyWater exploits DLL side-loading in espionage affecting nine nations.

2 min read
AI Security

AppOmni Unveils Marlin AI for SaaS Security Analysis

Marlin AI steps in with autonomous SaaS threat investigations.

2 min read
Threat Intelligence

Megalodon Campaign Pushed 5,718 Malicious Commits Into GitHub Repos in Six Hours

An automated backdooring operation abused compromised GitHub credentials to silently inject base64-encoded bash payloads into CI/CD workflows across more than 5,500 public repositories on May 18.

2 min read
Policy & Regulation

CERT-In Tightens the Clock: Patch Internet-Facing Bugs in 12 Hours

India's national CERT cites AI-assisted exploit development as the reason small teams now have less than a working day to close exposed holes.

3 min read
Threat Intelligence

The Bot That Learned to Lie: Inside the New Generation of AI-Driven DDoS

Defenders describe attack waves that pause, study traffic patterns, and resume from fresh infrastructure — behavior that looks less like a script and more like a sparring partner.

3 min read
© 2026 Threat Vectr